articlesמקור: PortSwigger Research5.8.2026
מתקפות Desync מבוססות CRLF: עריפת ראשי זרמי HTTP
CRLF-Powered Desync Attacks: Beheading HTTP Streams

◆ סיכום AI
מאמר זה מציג כיצד CRLF injection, המכונה כאן CRLF-Power, מאפשרת מתקפות Desync חמורות על זרמי HTTP. החוקרים מראים שחולשת HTTP Header Injection מוערכת בחסר ועלולה להוביל לנזקים קטסטרופליים, מעבר ל-XSS או הפניות פתוחות.
# מהמקור
Abstract In this paper we’ll show that HTTP Header Injection is severely underestimated. Forget open redirects or Cross-Site Scripting and instead, embrace the catastrophic potential of the CRLF-Power
#crlf-injection#http-desync#web-security#vulnerability
קרא במקור